Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo nosm.ca

Group: dispossessor

Discovered by ransomware.live: 2024-04-19

Estimated attack date: 2023-06-03

Country: CA

Description:

Northern Ontario School of Medicine University is a public medical university in the Canadian province of Ontario. It is mandated both to educate doctors and to contribute to care in Northern Ontario's urban, rural and remote communities, and has cam...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 1

Third Party Employee Credentials: 1


External Attack Surface: 3



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse webnames.ca
  • dimitri.demetrakopoulos nosm.ca
  • chris.caddel nosm.ca
MX Records
  • alt2.aspmx.l.google.com.
  • alt1.aspmx.l.google.com.
  • aspmx.l.google.com.
  • aspmx3.googlemail.com.
  • aspmx2.googlemail.com.
TXT Records
  • apple-domain-verification=ycJ0MGOs9u7eQyi2
  • v=spf1 ip4:23.177.144.0/24 ip4:142.150.190.48/28 ip4:64.209.141.221/32 ip4:204.8.10.114/32 ip4:205.139.104.0/23 ip4:168.245.0.78/32 include:spf.nosm.ca include:_spf.google.com include:_spf.qualtrics.com ~all
  • n95u9e52khiqdh3t81hj1fm1aa
  • cisco-ci-domain-verification=4342d1e64eab03930653664df72fb11553969574424ae378b9ad0e1b7e18c7b0
  • MS=ms47572950
  • bcn=67CE4228-CC48-11EE-AB09-50F34D7027BB
  • MS=ms85697290
  • druide-validation-domaine=825f42384bb7bc3a5a558e561d7f414c
  • canva-site-verification=y8WCOTPfaibMf-PSfFbGXw
  • ncimrdmjmf9r3nqbdkq0t6uvdh
Cloud / SaaS Services Detected
Apple Microsoft 365 Cisco

Leak Screenshot:

Leak Screenshot